AI Weekly Malaysia

Back to items Summaries

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

ID
28607
Status
new
Published
25 Sep 2026, 9:18 PM
Fetched
26 Sep 2026, 1:02 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Excerpt

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

Summary

No summary yet. It will appear after the daemon summarizes this item.

Top